CVE-2024-40767
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
- Affected products
- Linuxmint, Openstack Nova, Ubuntu
- Openstack Nova
- < 27.4.1, 28.2.1, 29.1.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.9% (58th percentile)
- Weakness
- CWE-552
- NVD status
- Modified
- Published
- 2024-07-24
No indexed exploits for CVE-2024-40767 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-40767 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.